A role is a named set of permissions. You compose the roles your enterprise needs, then assign them to members.
Enterprise roles do not currently pass down permissions to sub-organisations, but this is planned for a future release. For now, roles are purely used to manage your enterprise itself.
Creating a role
Open Roles tab in your enterprise.
Select 'Create role'.
Enter a Name, for example
Engineering.Enter a Description, which identifies what a role does and who is assigned to it without reading the permissions.
Select the Permissions the role grants.
Select 'Create role' to finish creating the role.
A role grants nothing until it holds at least one permission, so an empty role cannot be saved. You can always go back and edit a role at any time after creating it.
What a role can grant
The role editor lists the permissions your enterprise can grant, grouped by the area each one applies to. Read the editor for the current list, and use the table below to plan.
| Area | Permissions | What they cover |
|---|---|---|
| Members | Read, add, update, remove | Seeing the member list, inviting people, changing the roles a member holds, and ending a membership. |
| Roles | Read, create, update, delete | Seeing roles, and composing or removing them. |
| Domains | Read, create, verify, delete | Seeing domains, adding one, verifying ownership, and removing one. |
| Single sign-on | Read, create, update, delete, route domains, set applications | Seeing connections, adding or removing one, choosing which domains route to it, and choosing which applications it may be used with. |
| Settings | Update | Changing the display name and the branding. |
Permission to read an area and permission to change it are granted separately. A role can therefore let someone audit single sign-on without letting them alter a connection.
The owner role
By default, every enterprise comes with an owner role which grants all permissions that is not shown in the roles list and cannot be modified or removed. Only one owner can be assigned at a given time, however, you can transfer ownership to a different member by using the dots menu in the member list.
Related pages
Members: Assigning roles to people.
Single sign-on: The configuration these permissions govern.
Members and roles: The fixed roles inside an organisation.